10-21-2017 02:21 AM - edited 03-12-2019 04:38 AM
Hi Cisco Support,
May we request for your assistance as we are having an issue on "show dmvpn" as tunnel state are "ike". Is this a behavior of dmvpn? We have 4 tunnels, 1 is "UP" and 3 is"IKE". tunnel ips are reachable on Spoke router side to HUB.
Software Version is 15.2(4)M6a C2900 Router
Thanks!
Solved! Go to Solution.
10-21-2017 09:39 AM
Hi
Ike state means that your crypto hasn't been negotiated between peers.
You're pinging the wan IP used by the tunnel interface to come up but not the tunnel IP itself.
can you share the output of show cry isak sa and show cry ipsec sa?
Have you run some debug crypto to see why you're stuck in Ike state?
Are you using certificates or preshared key for ipsec? Validated that the key or certificates are correct.
10-21-2017 09:39 AM
Hi
Ike state means that your crypto hasn't been negotiated between peers.
You're pinging the wan IP used by the tunnel interface to come up but not the tunnel IP itself.
can you share the output of show cry isak sa and show cry ipsec sa?
Have you run some debug crypto to see why you're stuck in Ike state?
Are you using certificates or preshared key for ipsec? Validated that the key or certificates are correct.
10-23-2017 02:40 AM
10-23-2017 08:47 PM
10-24-2017 10:12 AM
10-24-2017 11:28 PM
10-25-2017 04:51 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide